Monitoring Splunk

Cannot stop capturing events for localhost

kgeil
Explorer

Hi, I have Splunk set up on my workstation, but do not want to monitor the workstation itself. I have gone to Manager » Data inputs » Event log collections » localhost, and cleared all selected logs (application, security, and system), and hit save. When I go back there, however, these three logs are back in the Selected Log(s) box. I have disabled all other data inputs, but still, I get events for my workstation. Am I doing something wrong? Do I need to send these events to a nullqueue, as described in the link below?

http://docs.splunk.com/Documentation/Splunk/4.2.4/Deploy/Routeandfilterdatad

Thanks,

Kevin

Tags (1)
0 Karma

gpt
New Member

Hello. I'm interested in doing something like that because of the license's warnings. I'm monitorizing several servers from my computer but I don't want my computer's logs at all. I noticed the most info Splunk get is from my computer so I already have 3 warnings!

I have tried to put my computer's info into another index and disable it but I'm not sure that's going to work. I'd like to send my computer's info to a null queue and I tried but I wasn't able.

What exactly do I have to modify in outputs.conf? What about props.conf?
I'll aprecciate any help!

Thank you!!

PD. Sorry about my English!

0 Karma

kgeil
Explorer

Cool, Thank you. I'll be checking that out tomorrow. If you know of a link for editing outputs.conf, I'd love to read it (I'm not in front of my splunk installation right now, so I can't read the file itself).

Thanks again,

Kevin

0 Karma

gekoner
Communicator

Yes you need to either send them to a null queue or if you don't want ANY data from your local host, remove or edit your outputs.conf file

0 Karma

kgeil
Explorer

I have cleaned out all indexes. They begin showing up immediately after that, all new events.

Thanks,

Kevin

0 Karma

rroberts
Splunk Employee
Splunk Employee

Are you just seeing old indexed events? Have you cleaned out the index? Or are new events still coming in?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...